PT-2025-13796 · Openemr · Openemr

Published

2025-03-31

·

Updated

2025-04-30

·

CVE-2025-30149

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.3
Description The issue concerns reflected cross-site scripting (XSS) in the AJAX Script interface, specifically in the layout listitems ajax.php file via the target parameter. This allows for potential XSS attacks.
Recommendations For versions prior to 7.0.3, update to version 7.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the layout listitems ajax.php file or avoiding the use of the target parameter in the AJAX Script interface until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-30149
GHSA-FWFV-8583-6RR7

Affected Products

Openemr